4 ms·
1) Nonsense. If you don't trust other people's code, you're screwed. You put yourself into the position where you have to audit your OS code, your CPU code, cod
by bufferoverflow 4y ago
1) Nonsense. If you don't trust other people's code, you're screwed. You put yourself into the position where you have to audit your OS code, your CPU code, code of every driver that runs in your system. None of which you did.
2) Isn't WebRTC open source too?
3) Their code, their decisions.
- fartcannon 4y agoTheir code, their decisions is why it's bad. If the decide to start tattling to Microsoft too, what are you going to do? If it's open, we can fork it and move on with your lives. Free and open gives you and me the power to control our own communication.
- bufferoverflow 4y ago> If the decide to start tattling to Microsoft too, what are you going to do? That would be obvious in their source code, wouldn't it? I would stop using them then.
- fartcannon 4y agoIts not open enough to verify that.
- runnerup 4y agoYou went from: > What's not trust worthy exactly? to: > Their code, their decisions. It's okay to be a fanboy! Evangelism is needed for any great product/company/ideology. But on HN you'll get typically called out for disingenuous or bad-faith lines of rhetoric. The person above gave you a perfectly reasonable answer to your original question of "What about Signal is not trustworthy?". It'd be kind to acknowledge that they at least have a single iota of merit.
- bufferoverflow 4y ago> You went from: > > > What's not trust worthy exactly? > > to: > > > Their code, their decisions. Two separate comments addressing two different points. One doesn't follow from the other. Stop arguing in such dishonest manner.
- dijit 4y agoThese are extremely unconvincing and rather shallow refutations. I expect more of people on this forum honestly. Taking the core of your argument: "Trust". The point of E2EE is that we don't trust the network. We put all the trust in the client, something we control. Or at the very least we seperate our concerns. (please refer to this lovely interactive "Tor" diagram by the EFF for what I mean by splitting out concerns: https://www.eff.org/pages/tor-and-https https://www.eff.org/pages/tor-and-https ) Not being able to run your own client is a pretty big problem. At the very least in that case you should expect to be able to run on another network.. Otherwise that's a lot of trust for one entity and it's not different than just using TLS with HPKP/CA pinning To give a direct refutation to one of your points: "Isn't WebRTC open source too?" It is, but they're using native libraries which are compiled. Like I said, it's a good argument, but the result is that they don't have reproducible builds. > Their code, their decisions. Extremely dismissive, almost to the point of insulting. It is absolutely not true that they are above criticism because they built something. They've positioned their product as a security product. Thus it will be judged on those merits. There are many pro-signal zealots who will bend over backwards to defend it in all circumstances. It's intellectually dishonest to do so in the face of valid criticisms. I will shut up when federation is supported, or you can run your own network, or you can bring third party clients. You need this to be able to trust your client, because the point is to decouple some trust from a single entity. that's what e2ee is!
- bufferoverflow 4y ago> These are extremely unconvincing and rather shallow refutations. That's not a refutation of my counterarguments at all. It just shows you're frustrated and talked yourself into a corner. We both know you don't audit your OS code, your drivers code, your hardware. All of them can be leaking your secret messages. > Extremely dismissive, almost to the point of insulting. Another non-refutation, another frustration, because you have no counterargument. > It is absolutely not true that they are above criticism Straw man logical fallacy. I never claimed they were above criticism. Criticize all you want. But expect your arguments disassembled. > You need this to be able to trust your client, because the point is to decouple some trust from a single entity. Without auditing your OS, your drivers and your hardware it's pointless. Any of them can leak your messages. Yet you're fine with it.